PT-2019-3346 · Cisco · Cisco Unified Contact Center Express

Publicado

2019-09-04

·

Atualizado

2020-10-08

·

CVE-2019-12633

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Unified Contact Center Express (Unified CCX) (affected versions not specified)
Description A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The issue is due to improper validation of user-supplied input on the affected system. An attacker could exploit this by sending a crafted request to the user of the web application. If the request is processed, the attacker could access the system and perform unauthorized actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03476
CVE-2019-12633

Produtos afetados

Cisco Unified Contact Center Express